Companies Selling Software to the U.S. Government Soon Must Attest to Compliance with NIST Guidance on Software Supply Chain Security
- Software companies that sell commercial software products to federal agencies soon must begin attesting to their compliance with guidance designed to enhance the security of the software supply chain. Under a new White House Office of Management and Budget (OMB) memorandum issued September 14,... ›
DOJ Cyber-Fraud Initiative Highlights Potential Civil Liability for Failing to Meet Federal Cybersecurity Requirements
By: Tina D. Reynolds
The Department of Justice (DOJ) has created a new Civil Cyber-Fraud Initiative to use the power of the False Claims Act (FCA) to initiate suits against federal contractors and grant recipients that fall short of their regulatory and contractual cybersecurity obligations. This initiative, announced... ›U.S. Congress Introduces Bill that Would Require Mandatory 24 Hour Cyber Breach Notification for Government Agencies, Contractors, and Operators of Critical Infrastructure
By: Alex Iftimie and Tina D. Reynolds
This week, U.S. Senator Mark Warner (D-VA), chair of the Senate Intelligence Committee, and a broad group of bipartisan co-sponsors, introduced legislation that would require government agencies, contractors, and operators of critical infrastructure to report cyber incidents to the U.S. Cybersecurity and Infrastructure Security... ›Executive Order on Cybersecurity Expands Mandatory Breach Notification and Supply Chain Security Requirements for Government Contractors
By: Tina D. Reynolds, Alex Iftimie and Sandeep N. Nandivada
On May 12, 2021, the Biden administration issued an ambitious Executive Order on Improving the Nation’s Cybersecurity (EO) declaring the prevention, detection, assessment, and remediation of cyber incidents to be a “top priority and essential to national and economic security.” Over 8,000 words long,... ›Data Rights: Current Developments & Pending DOD Changes
By: W. Jay DeVecchio
Jay DeVecchio recently published a Briefing Paper for Thomson Reuters covering recent developments in the Department of Defense’s (DOD) Defense Federal Acquisition Regulation Supplement (DFARS) data rights provisions. Dissecting the DOD’s recent actions and attitudes, this article contextualizes the upcoming DOD proposal as it... ›U.S. Government Responds to SolarWinds Hack, Seeks to Establish New Norms for Cyber Espionage
By: Miriam H. Wugmeister, Alex Iftimie, Brandon L. Van Grack and Tina D. Reynolds
After much anticipation and hints, the U.S. Government announced a series of measures to respond to recent Russian actions against the United States, including the SolarWinds intrusion campaign. The measures underscore that companies are not in a position and should not be left to... ›Top Cybersecurity Considerations for Government Contractors in 2021
By: Tina D. Reynolds
Although it was already apparent, recent events have made it even clearer that cybersecurity is an essential concern for government contractors. The coming year is poised to include many cybersecurity-related changes and developments. Below we highlight just a few: Continued Rollout of Department of... ›Deadline Fast Approaching for DoD Contractors and Subcontractors to Report Cyber Compliance
By: Tina D. Reynolds
As we previously reported, the Department of Defense (DoD) has issued an interim rule that requires all contractors and subcontractors that store, process, generate, transmit or access “covered defense information” to conduct a self- assessment of compliance with NIST SP 800-171 using the DoD... ›Breaking DOD’s Code: How to Figure Out and Resist What DOD Really, Truly Wants to Do to Your Data Rights
By: W. Jay DeVecchio
Your rights in technical data and software are at greater risk today than at any time during the last 25 years. The Department of Defense (“DOD”) is proposing the authority to rewrite commercial software licenses in ways never before seen and guaranteed to be... ›U.S. District Court for the District of Columbia Finds That Alleged Cybersecurity Vulnerability Is Not Material Under False Claims Act
By: Tina D. Reynolds and Victoria Dalcourt Angle
In a decision sure to bring some comfort to contractors providing information technology equipment and services to the federal government, a U.S. district court judge recently granted a motion to dismiss a False Claims Act (FCA) suit, finding that the relator both failed to... ›